CVE-2017-4960

Source
https://cve.org/CVERecord?id=CVE-2017-4960
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-4960.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-4960
Aliases
Published
2017-03-10T01:59:00.143Z
Modified
2026-04-10T04:02:30.340779Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in Cloud Foundry release v247 through v252, UAA stand-alone release v3.9.0 through v3.11.0, and UAA Bosh Release v21 through v26. There is a potential to subject the UAA OAuth clients to a denial of service attack.

References

Affected packages

Git / github.com/cloudfoundry/uaa

Affected ranges

Type
GIT
Repo
https://github.com/cloudfoundry/uaa
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.9.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.9.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.9.2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.9.3"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.9.4"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.9.5"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.9.6"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.9.7"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.9.8"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.10.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.11.0"
        }
    ]
}
Type
GIT
Repo
https://github.com/cloudfoundry/uaa-release
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "21"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "22"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "23"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "24"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "24.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "24.2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "24.3"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "24.4"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "24.5"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "24.6"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "25"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "26"
        }
    ]
}

Affected versions

1.*
1.0.1
1.0.3
1.1
1.1.1
1.1.2
1.2.0
1.2.6
1.4.0
1.4.1
1.4.2
1.4.3
1.4.5
1.4.6
1.4.7
1.5.0
1.5.2
1.5.2.1
1.5.3
1.5.4
1.5.4.1
1.6.1
1.6.2
1.8.0
3.*
3.10.0
3.11.0
3.8.0
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
3.9.5
3.9.6
3.9.7
3.9.8
Other
ci-upgrade
travis-success-1475
travis-success-1478
travis-success-1497
v10
v11
v12
v14
v15
v16
v17
v18
v19
v2
v20
v21
v22
v23
v24
v25
v26
v3
v6
v7
v8
v9
v12.*
v12.3
v24.*
v24.1
v24.2
v24.3
v24.4
v24.5
v24.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-4960.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "247.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "248.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "249.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "250.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "251.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "252.0"
            }
        ]
    }
]